๐Ÿ” CVE Alert

CVE-2026-108720

MEDIUM 4.3

phpIPAM through 1.8.3 Missing Authorization in Customers, Locations and NAT Pages

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

phpIPAM through 1.8.3 contains a missing authorization vulnerability that allows authenticated low-privilege users to view restricted subnets and addresses because customer, location and NAT pages skip Subnets::check_permission. Attackers can open customer objects.php, single-location.php or nat_details.php to read IP addresses, CIDRs, hostnames and MAC addresses from sections they cannot access.

CWE CWE-862
Vendor phpipam
Product phpipam
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for phpipam phpipam

Be the first to know when new medium vulnerabilities affecting phpipam phpipam are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

phpipam / phpipam
0 โ‰ค 1.8.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind/phpipam-tools-cross-section-address-disclosure github.com: https://github.com/phpipam/phpipam/blob/e8010751d491e485acefa5787fb0e518eb948771/app/tools/customers/customer/objects/ipaddresses.php#L69-L110 github.com: https://github.com/phpipam/phpipam/blob/e8010751d491e485acefa5787fb0e518eb948771/app/tools/locations/single-location.php#L129-L195 github.com: https://github.com/phpipam/phpipam/blob/e8010751d491e485acefa5787fb0e518eb948771/app/tools/nat/nat_details.php#L16-L45 github.com: https://github.com/phpipam/phpipam vulncheck.com: https://www.vulncheck.com/advisories/phpipam-through-1.8.3-missing-authorization-in-customers-locations-and-nat-pages

Credits

HaiND from the Post and Telecommunication Institute of Technology